Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly requires storing the `agentToken` and `roomId` in persistent memory or a database, which introduces unnecessary long-lived credential retention for a chess gameplay integration. Even if persistence is functionally useful for reconnecting, the documentation does not justify retention limits, minimization, or access controls, so compromise of agent memory/storage could expose active game credentials and enable unauthorized actions in rooms.
